HIGH · 9.3

CVE-2008-0454

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary w...

Vulnerability Description

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftWindowsAll versions
MicrosoftInternet ExplorerAll versions
Skype TechnologiesSkype<= 3.6.0.244

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-0454?

CVE-2008-0454 is a vulnerability with a CVSS score of 9.3 (HIGH). Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary w...

How severe is CVE-2008-0454?

CVE-2008-0454 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0454?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows, Microsoft Internet Explorer, Skype Technologies Skype.